I care about the security and correctness of the code. I only care about the author who wrote it if they are someone known for low-quality, insecure, or malicious code.
If Linus Torvalds is convicted of genocide and child abuse tomorrow I'm going to continue using Linux as usual.
If you're part of a group and a chunk of them decide to leave, there's no point saying "why do you care about X? It doesn't affect the group."
It's their right to leave.
The other side is that who you associate with defines that group. So if it was a murderer that wrote a file system, then the software project gets defined by that.
It becomes hard to attract contributors when the project gets defined by the actions of one of its participants. Project leaders then have to make a decision since inaction is also a decision.
There is a point where the shaming and shunning stops being useful and becomes bullying.
We see this all the time in politics worth people liking "their team" too much and denigrating normal citizens just for their opinions and choices.
I'm unaware of anyone ever making a decision about contributing to a software project based on secret police level surveillance of current team members political or religious opinions. Even classified DoD stuff I've been involved in isn't that creepy.
Its important to focus discussion on extremes such as murders when the actual goal is to make sure Republicans are unemployable.
I would not give their contributions extra attention (you should be suspect of all changes, regardless of the author) and I would not ban them from contributing unless they became disruptive or subversive to the project.
They served their time; you don't need to punish them further. They are probably even less likely to commit fraud when their employer is aware of a previous fraud conviction.
The worst fraudsters don't come with a "convicted of fraud" warning—they have evaded being caught and will seem just like any other contributor.
It is not about punishing them, it is about reducing the risk of others. Having served time is, at best, no indication of whether a person will revert to their former behavior.
> The worst fraudsters don't come with a "convicted of fraud" warning—they have evaded being caught and will seem just like any other contributor.
This is no reason for not using what information you do have.
Note: I see that you have edited your original post to address these points, but I think they still stand, as expanded on in the continuing discussion below. Your statement "they are probably even less likely to commit fraud when their employer is aware of a previous fraud" seems to be in agreement with what I have been saying.
- Small (and well scrutinized) patches from this person are fine
- At some point forgiveness is due, maybe 3 years is at that point depending on the severity of their backdoor